Showing posts with label Legal. Show all posts
Showing posts with label Legal. Show all posts

Tuesday, January 24, 2012

Unsecured Video Conferencing Systems May be Exposing Your Meetings





"SAN FRANCISCO — One afternoon this month, a hacker took a tour of a dozen conference rooms around the globe via equipment that most every company has in those rooms; videoconferencing equipment.

With the move of a mouse, he steered a camera around each room, occasionally zooming in with such precision that he could discern grooves in the wood and paint flecks on the wall. In one room, he zoomed out through a window, across a parking lot and into shrubbery some 50 yards away where a small animal could be seen burrowing underneath a bush. With such equipment, the hacker could have easily eavesdropped on privileged attorney-client conversations or read trade secrets on a report lying on the conference room table.

In this case, the hacker was HD Moore, a chief security officer at Rapid7, a Boston based company that looks for security holes in computer systems that are used in devices like toaster ovens and Mars landing equipment. His latest find: videoconferencing equipment is often left vulnerable to hackers."
Read the rest of this article here: Flaws in videoconferencing systems put boardrooms at risk

Monday, August 22, 2011

Hacking Group Anonymous Breaches InfraGard

On August 18th hacking group Anonymous published documents stolen from Richard Garcia, senior vice president of Vanguard Defense Industries. The collection of documents contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen 'counter-terrorism' documents classified as 'law enforcement sensitive' and 'for official use only.'


Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.


One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.



Monday, May 23, 2011

Massachusetts Executive Office of Labor and Workforce Development Breached

Client names, social security numbers, email addresses and residential addresses and bank account detail of users of the Massachusetts Executive Office of Labor and Workforce Development claim system. The 1,200 system users were warned that their personal details may have been accessed by a data-stealing worm named W32.QAKBOT.

Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.

Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.

Friday, March 4, 2011

Do you consider your ZIP code "personal identification information" ?

The California Supreme Court does.  In a recent decision, the California Supreme Court ruled that a ZIP code is "personal identification information" for purposes of California Civil Code §1747.08. As a provision of the Song-Beverly Credit Card act of 1971, California Civil Code §1747.08 prohibits prohibits businesses, as a condition to accepting a credit card as payment for goods or services, from requesting and recording personal identification from credit card holders during credit card transactions. Personal identification is further defined in the statute as:
"information concerning the cardholder, other than information set forth on the credit card, and including, but not limited to, the cardholder’s address and telephone number."
The lawsuit was filed by a private citizen against retailer Williams-Sonoma after a ZIP code was requested at checkout and was later used in conjunction with other information to determine the customer's address for marketing purposes.

This decision comes as a further reminder to credit card processing retailers of the increasing complexity of credit card compliance. With the new Payment Card Industry Data Security Standards (PCI-DSS) and decisions such as this one, non-compliance is becoming more costly than ever. 

Does your organization process credit cards? Would your business be hurt by losing the ability to process credit cards? If you answered yes it is time to discover your compliance requirements and start working towards meeting the standards put in place by credit card companies and the courts. A great place to start is Attevo's DLP Toolkit where you can search a database of compliance regulations tailored to your business.

Tuesday, February 8, 2011

Ignorance of the Law is No Excuse

Many healthcare providers and vendors could find themselves claiming ignorance was as an excuse for not complying with the new HITECH Act regulations. HITECH compliance regulations are like a traffic sign; by simply doing business you are subject to the government’s "signs" regarding compliance regulations. The HITECH Act (Health Information Technology for Economic and Clinical Health) applies to healthcare providers, health insurance companies, clearinghouses, and business associates. A business associate is broadly defined as vendors, service providers, or even consulting and staffing companies.  Yes. That is correct. Business associates must comply with this law. What exactly is a business associate? Well the HITECH Act defines it as anyone who provides…

"... a function or activity involving the use or disclosure of individually identifiable health information, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, billing, benefit management, practice management, and repricing?" [45 CFR §160.103(1)(i)(A)]; or
"... legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services to or for such covered entity" [45 CFR §160.103(1)(ii)]

Do you need to comply with this law? Not sure? The best step to take is to discuss it with your legal counsel.  While you’re at it, you might as well discuss other regulations you must comply with and put together some policies and procedures that address them. This might be more work than you expected, but it will be worth it in the long run. The cost of compliance is much lower than if you are found guilty of non-compliance. Try $5 million dollars less.  Now go do your homework and read up on the regulations you must follow. The DLP Toolkit Regulation Finder is a great place to start.

Tuesday, December 21, 2010

US Bank Accused of Data Breach Cover-Up

Two small business owners find themselves at the center of a class action lawsuit against banking giant US Bank over the accusation of a large scale data breach cover-up. The family-owned online Paintball retailer, Paintball Punks, received 9 orders that were placed using US Bank credit cards. As was standard protocol, the credit card security numbers and billing addresses were verified. Weeks later, US Bank customers began disputing the charges and US Bank recouped their losses by doing "charge backs" where they essentially take back the money that was given to the retailer.


These charge backs cost Paintball Punks over  $11,000, while this amount seems small, the class action law suit was filed due to the unknown scope of the alleged breach. After investigating the claims by US Bank, one owner claims that a US Bank employee divulged that there had been a breach, but it did not go public. The alleged cover-up is in violation of state and federal data breach laws. U.S. Bank maintains that there was no breach and that the claims made in this lawsuit are wholly without merit.